
StopDefender
Stop Windows Defender programmatically
adversarial-attackimpersonation-toolspost-exploitation+2

Stop Windows Defender programmatically

A windows token impersonation tool

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.